CCI-000574
CCI-000574 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The information system owner will update the security plan as necessary to address changes to information system/environment of operation or problems identified during plan implementation or security control assessments. Documentation of security plan updates are required as an audit trail.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the audit records of security plan updates to verify the security plan is current. The purpose of the reviews is to validate the organization is updating the Information System (IS) security plan to address changes to the IS, its environment of operation, or problems identified during plan implementation or security control assessments.
Compelling Evidence
1.) Audit records of system security plan (SSP) updates that include changes to the information system, its environment, operations, or problems identified during plan implementation or security control assessments.